This discussion is archived
2 Replies Latest reply: Oct 24, 2012 4:36 AM by 828074 RSS

decrypt "%SignonUserPswd"

828074 Newbie
Currently Being Moderated
In the Signon PeopleCode there exists "%SignonUserPswd"; but it is encrypted. Has anyone found a way to decrypt it?

for example stuart becomes s+b1yCxg/XFeHXe5YZvpW4QQZuoMV4/FOd6kebBfyekfNxTKsjXuP4pRHR/GH3rTGcrfydh8/bInnZFLzhH+OQAA

Kind Regards, Bart
  • 1. Re: decrypt "%SignonUserPswd"
    HakanBiroglu Oracle ACE
    Currently Being Moderated
    Do not try to decrypt it, it will not work.
    Even if someone knows, it will not be shared, this is a major security bridge.

    If you need this for something like SSO, you can rather encrypt the password supplied and check that with the encrypted database value.
    See also {thread:id=650835}
  • 2. Re: decrypt "%SignonUserPswd"
    828074 Newbie
    Currently Being Moderated
    Thanks Hakan for your reaction.

    No I don't need it for SSO, but I wanted to write my own business interlink (to replace "LDAP_BIND") to validate passwords.

    Because they want me to allow students, whose account has expired on the LDAP server but use the correct password, access to a specific selfservice page.

    (In my opinion "LDAP_BIND" does only provide a return status "-1" when the validation fails, but no information why.)

    Kind regards, Bart

Legend

  • Correct Answers - 10 points
  • Helpful Answers - 5 points